Recital 1

Recital 1

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(1)

This Regulation has been drafted in accordance with the TIBER-EU framework and mirrors the methodology, process and structure of threat-led penetration testing (TLPT) as described in TIBER-EU. Financial entities subject to TLPT may refer to and apply the TIBER-EU framework, or one of its national implementations, in as much as that framework or implementation is consistent with the requirements set out in Articles 26 and 27 of Regulation (EU) 2022/2554 and this Regulation. The designation of a single public authority in the financial sector that is responsible for TLPT-related matters at national level in accordance with Article 26(9) of Regulation (EU) 2022/2554 should be without prejudice to the competence of competent authorities entrusted at Union level for the supervision of certain financial entities in accordance with Article 46 of that Regulation such as, for instance, the European Central Bank for significant credit institutions which are to be considered competent for TLPT-related matters. Where only some of the tasks related to TLPTs are delegated to another national authority in the financial sector pursuant to Article 26(10) of Regulation (EU) 2022/2554, the competent authority of the financial entity referred to in Article 46 of that Regulation should remain the authority for the TLPT-related tasks that have been not delegated.

Luxembourg specificity
cadre TIBER-LU (BCL et CSSF), Implementation Document revise le 20 juin 2025

In Luxembourg, the competent TLPT authority under Article 46 of DORA is the CSSF, which jointly runs the TIBER-LU framework with the BCL. The TIBER-LU Implementation Document was revised on 20 June 2025 to align with the TIBER-EU version revised by the ECB on 11 February 2025. For Luxembourg credit institutions classified as significant, the ECB retains its Article 46 competence, creating a dual governance that must be documented.

Luxgap practice: from the scoping phase, confirm whether your entity falls under direct ECB or CSSF supervision, and explicitly align your test with the TIBER-LU Implementation Document of 20 June 2025 to avoid any gap with the RTS.